download:

/releases/win32/ClaudeSetup.exe

Full analysis: https://app.any.run/tasks/60e31995-f89b-4870-a870-826da83418dc
Verdict: Malicious activity
Analysis date: February 27, 2026, 06:43:40
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
golang
anti-evasion
fingerprinting
nodejs
rust
websocket
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 9 sections
MD5:

B74DA59D7C2CE09160AD9B2317442162

SHA1:

B837DD9CE7A9993C67B478883008536CE4411938

SHA256:

15EA623FD13483B369353E035A5F7291662847511EC523CF5F0B8B596F5E9122

SSDEEP:

98304:DB3nH/OL0cHjhNjJSJCf6cLAaOhVfVZYRs9FnVG/qJaK0HZSCeb:B

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Application launched itself

      • ClaudeSetup.exe (PID: 7456)
      • claude.exe (PID: 1356)
      • claude.exe (PID: 7980)
      • claude.exe (PID: 1832)
      • claude.exe (PID: 5916)
      • claude.exe (PID: 8672)
    • Reads the date of Windows installation

      • ClaudeSetup.exe (PID: 7456)
    • Executes as Windows Service

      • cowork-svc.exe (PID: 1728)
    • The process checks if it is being run in the virtual environment

      • cowork-svc.exe (PID: 1728)
    • Reads settings of System Certificates

      • cowork-svc.exe (PID: 1728)
      • claude.exe (PID: 1356)
      • claude.exe (PID: 7980)
      • claude.exe (PID: 1832)
      • claude.exe (PID: 5916)
      • claude.exe (PID: 8672)
    • The process creates files with name similar to system file names

      • claude.exe (PID: 1356)
  • INFO

    • Reads security settings of Internet Explorer

      • ClaudeSetup.exe (PID: 7456)
      • ClaudeSetup.exe (PID: 6472)
      • explorer.exe (PID: 7980)
      • explorer.exe (PID: 2420)
    • The sample compiled with english language support

      • ClaudeSetup.exe (PID: 7456)
    • Checks supported languages

      • ClaudeSetup.exe (PID: 6472)
      • ClaudeSetup.exe (PID: 7456)
      • cowork-svc.exe (PID: 1728)
      • claude.exe (PID: 7660)
      • claude.exe (PID: 4944)
      • claude.exe (PID: 7176)
      • claude.exe (PID: 5760)
      • claude.exe (PID: 1356)
      • claude.exe (PID: 7432)
      • claude.exe (PID: 1980)
      • claude.exe (PID: 2000)
      • claude.exe (PID: 7980)
      • claude.exe (PID: 1656)
      • claude.exe (PID: 8048)
      • claude.exe (PID: 8332)
      • claude.exe (PID: 204)
      • claude.exe (PID: 1832)
      • claude.exe (PID: 4344)
      • claude.exe (PID: 3324)
      • claude.exe (PID: 2216)
      • claude.exe (PID: 5916)
      • claude.exe (PID: 7236)
      • claude.exe (PID: 8176)
      • claude.exe (PID: 3324)
      • claude.exe (PID: 8672)
      • claude.exe (PID: 7260)
      • claude.exe (PID: 5704)
      • claude.exe (PID: 5584)
    • Process checks computer location settings

      • ClaudeSetup.exe (PID: 7456)
      • claude.exe (PID: 5760)
      • claude.exe (PID: 1356)
      • claude.exe (PID: 7432)
      • claude.exe (PID: 2000)
      • claude.exe (PID: 1980)
      • claude.exe (PID: 7980)
      • claude.exe (PID: 1832)
      • claude.exe (PID: 5916)
      • claude.exe (PID: 8672)
    • Reads the computer name

      • ClaudeSetup.exe (PID: 7456)
      • ClaudeSetup.exe (PID: 6472)
      • cowork-svc.exe (PID: 1728)
      • claude.exe (PID: 7176)
      • claude.exe (PID: 4944)
      • claude.exe (PID: 1356)
      • claude.exe (PID: 7980)
      • claude.exe (PID: 8048)
      • claude.exe (PID: 8332)
      • claude.exe (PID: 204)
      • claude.exe (PID: 1832)
      • claude.exe (PID: 2216)
      • claude.exe (PID: 3324)
      • claude.exe (PID: 5916)
      • claude.exe (PID: 3324)
      • claude.exe (PID: 8176)
      • claude.exe (PID: 8672)
      • claude.exe (PID: 5704)
      • claude.exe (PID: 5584)
    • Reads Environment values

      • ClaudeSetup.exe (PID: 7456)
      • ClaudeSetup.exe (PID: 6472)
      • claude.exe (PID: 1356)
      • claude.exe (PID: 7980)
      • claude.exe (PID: 1832)
      • claude.exe (PID: 5916)
      • claude.exe (PID: 8672)
    • Drops script file

      • firefox.exe (PID: 8428)
      • firefox.exe (PID: 9036)
      • ClaudeSetup.exe (PID: 6472)
      • claude.exe (PID: 1356)
      • firefox.exe (PID: 8396)
      • claude.exe (PID: 7980)
      • claude.exe (PID: 1832)
      • claude.exe (PID: 5916)
      • claude.exe (PID: 8672)
      • firefox.exe (PID: 7916)
    • Create files in a temporary directory

      • ClaudeSetup.exe (PID: 7456)
      • ClaudeSetup.exe (PID: 6472)
      • claude.exe (PID: 1356)
    • Reads the machine GUID from the registry

      • ClaudeSetup.exe (PID: 7456)
      • ClaudeSetup.exe (PID: 6472)
      • cowork-svc.exe (PID: 1728)
      • claude.exe (PID: 1356)
      • claude.exe (PID: 7980)
      • claude.exe (PID: 204)
      • claude.exe (PID: 1832)
      • claude.exe (PID: 5916)
      • claude.exe (PID: 8672)
    • Checks proxy server information

      • ClaudeSetup.exe (PID: 6472)
    • Creates files or folders in the user directory

      • ClaudeSetup.exe (PID: 6472)
      • claude.exe (PID: 7660)
      • claude.exe (PID: 1356)
      • claude.exe (PID: 4944)
      • claude.exe (PID: 1656)
      • claude.exe (PID: 7980)
      • claude.exe (PID: 8332)
      • claude.exe (PID: 204)
      • claude.exe (PID: 4344)
      • claude.exe (PID: 2216)
      • claude.exe (PID: 1832)
      • claude.exe (PID: 7236)
      • claude.exe (PID: 5916)
      • claude.exe (PID: 3324)
      • claude.exe (PID: 7260)
      • claude.exe (PID: 8672)
      • claude.exe (PID: 5584)
    • There is functionality for taking screenshot (YARA)

      • ClaudeSetup.exe (PID: 7456)
      • claude.exe (PID: 1356)
    • Application based on Golang

      • ClaudeSetup.exe (PID: 7456)
      • cowork-svc.exe (PID: 1728)
    • Detects GO elliptic curve encryption (YARA)

      • ClaudeSetup.exe (PID: 7456)
      • cowork-svc.exe (PID: 1728)
    • Creates files in the program directory

      • cowork-svc.exe (PID: 1728)
    • Drops encrypted JS script (Microsoft Script Encoder)

      • ClaudeSetup.exe (PID: 6472)
    • Reads product name

      • claude.exe (PID: 1356)
      • claude.exe (PID: 7980)
      • claude.exe (PID: 1832)
      • claude.exe (PID: 5916)
      • claude.exe (PID: 8672)
    • Reads CPU info

      • claude.exe (PID: 1356)
      • claude.exe (PID: 7980)
      • claude.exe (PID: 1832)
      • claude.exe (PID: 5916)
      • claude.exe (PID: 8672)
    • Application based on Rust

      • claude.exe (PID: 1356)
    • Node.js compiler has been detected

      • claude.exe (PID: 7660)
      • claude.exe (PID: 1356)
    • Manual execution by a user

      • firefox.exe (PID: 8376)
      • claude.exe (PID: 7980)
      • claude.exe (PID: 1832)
      • claude.exe (PID: 5916)
      • claude.exe (PID: 8672)
      • firefox.exe (PID: 9036)
    • Application launched itself

      • firefox.exe (PID: 8396)
      • firefox.exe (PID: 8376)
      • firefox.exe (PID: 7916)
      • firefox.exe (PID: 9036)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 0000:00:00 00:00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 3
CodeSize: 2997760
InitializedDataSize: 361984
UninitializedDataSize: -
EntryPoint: 0x77b60
OSVersion: 6.1
ImageVersion: 1
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Anthropic, PBC
FileDescription: Claude Setup
FileVersion: 1.0.0.0
InternalName: ClaudeSetup
LegalCopyright: 2025 Anthropic PBC
OriginalFileName: ClaudeSetup.exe
ProductName: Claude
ProductVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
199
Monitored processes
57
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start claudesetup.exe claudesetup.exe cowork-svc.exe explorer.exe no specs explorer.exe no specs claude.exe no specs claude.exe no specs claude.exe no specs claude.exe claude.exe no specs claude.exe no specs claude.exe no specs claude.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs claude.exe no specs claude.exe no specs claude.exe no specs claude.exe claude.exe no specs claude.exe no specs claude.exe no specs claude.exe no specs claude.exe claude.exe no specs claude.exe no specs claude.exe no specs claude.exe claude.exe no specs claude.exe no specs claude.exe no specs claude.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
204"C:\Program Files\WindowsApps\Claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\Claude.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --user-data-dir="C:\Users\admin\AppData\Roaming\Claude" --gpu-preferences=SAAAAAAAAADoAAAEAAAAAAAAAAAAAGAAAQAAAAAAAAAAAAAAAAAAAEIAAAAAAAAAAAAAAAAAAAAQAAAAAAAAABAAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --field-trial-handle=2024,i,7143206388115763776,16533682769856264309,262144 --enable-features=DocumentPolicyIncludeJSCallStacksInCrashReports,EnableTransparentHwndEnlargement,PdfUseShowSaveFilePicker --disable-features=LocalNetworkAccessChecks,NetworkServiceSandbox,ScreenAIOCREnabled,SpareRendererForSitePerProcess,TraceSiteInstanceGetProcessCreation --variations-seed-version --trace-process-track-uuid=3190708993808206286 --mojo-platform-channel-handle=4472 /prefetch:8C:\Program Files\WindowsApps\Claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\claude.execlaude.exe
User:
admin
Company:
Anthropic
Integrity Level:
MEDIUM
Description:
Claude
Exit code:
0
Version:
1.1.4498
Modules
Images
c:\program files\windowsapps\claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\claude.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\version.dll
c:\windows\system32\wintrust.dll
1356"C:\Program Files\WindowsApps\Claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\Claude.exe" "claude:///"C:\Program Files\WindowsApps\Claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\claude.exeexplorer.exe
User:
admin
Company:
Anthropic
Integrity Level:
MEDIUM
Description:
Claude
Version:
1.1.4498
Modules
Images
c:\program files\windowsapps\claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\claude.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\wintrust.dll
1656"C:\Program Files\WindowsApps\Claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\Claude.exe" --type=crashpad-handler --user-data-dir=C:\Users\admin\AppData\Roaming\Claude /prefetch:4 --no-rate-limit --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\admin\AppData\Roaming\Claude\Crashpad --url=https://f.a.k/e --annotation=_productName=Claude --annotation=_version=1.1.4498 --annotation=plat=Win64 --annotation=prod=Electron --annotation=ver=40.4.1 --initial-client-data=0x4ac,0x4b0,0x4b4,0x4a8,0x4b8,0x7ff7ae74e774,0x7ff7ae74e780,0x7ff7ae74e790C:\Program Files\WindowsApps\Claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\claude.execlaude.exe
User:
admin
Company:
Anthropic
Integrity Level:
MEDIUM
Description:
Claude
Exit code:
0
Version:
1.1.4498
Modules
Images
c:\program files\windowsapps\claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\claude.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
1728"C:\Program Files\WindowsApps\Claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\resources\cowork-svc.exe"C:\Program Files\WindowsApps\Claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\resources\cowork-svc.exe
services.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Modules
Images
c:\program files\windowsapps\claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\resources\cowork-svc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\umpdc.dll
c:\windows\system32\ws2_32.dll
1832"C:\Program Files\WindowsApps\Claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\Claude.exe" "claude://claude.ai/magic-link#5aadbea081f9915ee05b8e702366e0f8:YWRtaW54QGxsbW9jci5jb20="C:\Program Files\WindowsApps\Claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\claude.exeexplorer.exe
User:
admin
Company:
Anthropic
Integrity Level:
MEDIUM
Description:
Claude
Exit code:
0
Version:
1.1.4498
Modules
Images
c:\program files\windowsapps\claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\claude.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
1980"C:\Program Files\WindowsApps\Claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\Claude.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\Claude" --secure-schemes=sentry-ipc --bypasscsp-schemes=sentry-ipc --cors-schemes=sentry-ipc --fetch-schemes=sentry-ipc --app-path="C:\Program Files\WindowsApps\Claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\resources\app.asar" --enable-sandbox --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=7 --time-ticks-at-unix-epoch=-1772173835808431 --launch-time-ticks=815318314 --field-trial-handle=2024,i,7143206388115763776,16533682769856264309,262144 --enable-features=DocumentPolicyIncludeJSCallStacksInCrashReports,EnableTransparentHwndEnlargement,PdfUseShowSaveFilePicker --disable-features=LocalNetworkAccessChecks,NetworkServiceSandbox,ScreenAIOCREnabled,SpareRendererForSitePerProcess,TraceSiteInstanceGetProcessCreation --variations-seed-version --trace-process-track-uuid=3190708992871164437 --mojo-platform-channel-handle=3816 --desktop-features="{\"nativeQuickEntry\":{\"status\":\"unavailable\"},\"quickEntryDictation\":{\"status\":\"unavailable\"},\"customQuickEntryDictationShortcut\":{\"status\":\"supported\"},\"plushRaccoon\":{\"status\":\"unavailable\"},\"quietPenguin\":{\"status\":\"unavailable\"},\"chillingSlothFeat\":{\"status\":\"unavailable\"},\"chillingSlothEnterprise\":{\"status\":\"supported\"},\"chillingSlothLocal\":{\"status\":\"supported\"},\"yukonSilver\":{\"status\":\"unsupported\",\"reason\":\"Missing HCS services: HNS, vmcompute\",\"unsupportedCode\":\"hcs_not_available\"},\"yukonSilverGems\":{\"status\":\"unsupported\",\"reason\":\"Missing HCS services: HNS, vmcompute\",\"unsupportedCode\":\"hcs_not_available\"},\"desktopTopBar\":{\"status\":\"supported\"},\"ccdPlugins\":{\"status\":\"supported\"}}" /prefetch:1C:\Program Files\WindowsApps\Claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\claude.execlaude.exe
User:
admin
Company:
Anthropic
Integrity Level:
LOW
Description:
Claude
Version:
1.1.4498
Modules
Images
c:\program files\windowsapps\claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\claude.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
2000"C:\Program Files\WindowsApps\Claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\Claude.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\Claude" --secure-schemes=sentry-ipc --bypasscsp-schemes=sentry-ipc --cors-schemes=sentry-ipc --fetch-schemes=sentry-ipc --app-path="C:\Program Files\WindowsApps\Claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\resources\app.asar" --enable-sandbox --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=6 --time-ticks-at-unix-epoch=-1772173835808431 --launch-time-ticks=814276393 --field-trial-handle=2024,i,7143206388115763776,16533682769856264309,262144 --enable-features=DocumentPolicyIncludeJSCallStacksInCrashReports,EnableTransparentHwndEnlargement,PdfUseShowSaveFilePicker --disable-features=LocalNetworkAccessChecks,NetworkServiceSandbox,ScreenAIOCREnabled,SpareRendererForSitePerProcess,TraceSiteInstanceGetProcessCreation --variations-seed-version --trace-process-track-uuid=3190708991934122588 --mojo-platform-channel-handle=2980 /prefetch:1C:\Program Files\WindowsApps\Claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\claude.execlaude.exe
User:
admin
Company:
Anthropic
Integrity Level:
LOW
Description:
Claude
Version:
1.1.4498
Modules
Images
c:\program files\windowsapps\claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\claude.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
2100"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5072 -prefsLen 39368 -prefMapHandle 5076 -prefMapSize 273101 -jsInitHandle 5080 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5008 -initialChannelId {1aae6ba5-cb2b-461b-8f76-96b915f91004} -parentPid 7916 -crashReporter "\\.\pipe\gecko-crash-server-pipe.7916" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 7 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\crypt32.dll
2216"C:\Program Files\WindowsApps\Claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\Claude.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --user-data-dir="C:\Users\admin\AppData\Roaming\Claude" --secure-schemes=sentry-ipc --bypasscsp-schemes=sentry-ipc --cors-schemes=sentry-ipc --fetch-schemes=sentry-ipc --field-trial-handle=1988,i,11747667930082690440,7727423131007773145,262144 --enable-features=DocumentPolicyIncludeJSCallStacksInCrashReports,EnableTransparentHwndEnlargement,PdfUseShowSaveFilePicker --disable-features=LocalNetworkAccessChecks,NetworkServiceSandbox,ScreenAIOCREnabled,SpareRendererForSitePerProcess,TraceSiteInstanceGetProcessCreation --variations-seed-version --trace-process-track-uuid=3190708989122997041 --mojo-platform-channel-handle=2356 /prefetch:3C:\Program Files\WindowsApps\Claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\claude.exe
claude.exe
User:
admin
Company:
Anthropic
Integrity Level:
MEDIUM
Description:
Claude
Exit code:
0
Version:
1.1.4498
Modules
Images
c:\program files\windowsapps\claude_1.1.4498.0_x64__pzs8sxrjxfjjc\app\claude.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
2420C:\WINDOWS\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shcore.dll
Total events
23 702
Read events
23 523
Write events
8
Delete events
171

Modification events

(PID) Process:(2420) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2420) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2420) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1356) claude.exeKey:HKEY_CLASSES_ROOT\claude
Operation:writeName:URL Protocol
Value:
(PID) Process:(1356) claude.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Spelling\Dictionaries
Operation:delete valueName:en-US
Value:
(PID) Process:(1356) claude.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Spelling\Dictionaries
Operation:delete valueName:en
Value:
(PID) Process:(1356) claude.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Spelling\Dictionaries
Operation:delete valueName:_Global_
Value:
(PID) Process:(7980) claude.exeKey:HKEY_CLASSES_ROOT\claude
Operation:writeName:URL Protocol
Value:
(PID) Process:(7980) claude.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Spelling\Dictionaries
Operation:delete valueName:en-US
Value:
(PID) Process:(7980) claude.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Spelling\Dictionaries
Operation:delete valueName:en
Value:
Executable files
0
Suspicious files
13
Text files
8
Unknown types
997

Dropped files

PID
Process
Filename
Type
7456ClaudeSetup.exeC:\Users\admin\AppData\Local\Temp\Claude-2361926732.msix.downloading
MD5:
SHA256:
7456ClaudeSetup.exeC:\Users\admin\AppData\Local\Temp\Claude-2361926732.msix
MD5:
SHA256:
6472ClaudeSetup.exeC:\Users\admin\AppData\Local\Temp\APPX.miu29jepxhr18bfgnf0hqjbgf.tmpbinary
MD5:562617187C573D8B41F6D1F35001041A
SHA256:4255C0A44EC2146F5A9CC3EADC938AA157E2E5CF47926F219BE566D42B47E89C
6472ClaudeSetup.exeC:\Users\admin\AppData\Local\Temp\APPX.3j6_u8pvu_ebajk_qjmvxoa6c.tmpbinary
MD5:562617187C573D8B41F6D1F35001041A
SHA256:4255C0A44EC2146F5A9CC3EADC938AA157E2E5CF47926F219BE566D42B47E89C
6472ClaudeSetup.exeC:\Users\admin\AppData\Local\Temp\APPX.rhnrm56jk4w0gpld233b7y2mg.tmpbinary
MD5:652D23EFE123B1260E0D4EF26A1402BB
SHA256:987213CEB4319D67A851E379B08BE47A1747464501482EA7ADF8856692F3FE7B
6472ClaudeSetup.exeC:\Users\admin\AppData\Local\Temp\APPX.ursv4w0dq2bm1hvky2oyymi1b.tmpbinary
MD5:C05E6D40A31AE2EA8BBDD5C7EF9F01F3
SHA256:1BBFE184ADABEEA422FEDF567F767AE99549216B86BE81935BC45A0725B45993
6472ClaudeSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:09B52C4D7CBFD4B1846A9ADB73096B64
SHA256:0144506E44FB95FBA81D42F44BB6F0F5E0BC8E143D299FD1A515B96BF6C33C43
6472ClaudeSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:B6BE1D91BA3E6F58FAC5AC2ECB376BE8
SHA256:7AF323B80418256F129B9D70DB4FAB27913D4336EC3683013E6C0D304697E6A4
6472ClaudeSetup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:D5B048712815C3B0CCD4FBACDA6AB621
SHA256:AE72F4A2647A0C0BBD0513FF08737038A014C3483FCAA8FBBF476DE093E4385B
6472ClaudeSetup.exeC:\Users\admin\AppData\Local\Temp\APPX.b75jqbqrr5digzkfdfqkzbzqh.tmpbinary
MD5:652D23EFE123B1260E0D4EF26A1402BB
SHA256:987213CEB4319D67A851E379B08BE47A1747464501482EA7ADF8856692F3FE7B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
638
TCP/UDP connections
283
DNS requests
278
Threats
12

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5276
MoUsoCoreWorker.exe
GET
304
40.127.240.158:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
6472
ClaudeSetup.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
US
binary
727 b
whitelisted
7248
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
508
svchost.exe
GET
304
40.127.240.158:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
whitelisted
6472
ClaudeSetup.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
US
binary
471 b
whitelisted
5276
MoUsoCoreWorker.exe
GET
304
40.127.240.158:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
5276
MoUsoCoreWorker.exe
GET
200
23.59.18.102:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
6472
ClaudeSetup.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA7VnKR%2FFdCaV3VeSxLTGlA%3D
US
binary
727 b
whitelisted
3996
SIHClient.exe
GET
304
74.179.77.204:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
5276
MoUsoCoreWorker.exe
GET
200
2.16.241.12:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
508
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2.16.241.205:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
5276
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7248
svchost.exe
40.126.31.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
7456
ClaudeSetup.exe
160.79.104.10:443
api.anthropic.com
ANTHROPIC
US
whitelisted
7456
ClaudeSetup.exe
35.190.46.17:443
downloads.claude.ai
GOOGLE-CLOUD-PLATFORM
US
whitelisted
6472
ClaudeSetup.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
whitelisted
www.bing.com
  • 2.16.241.205
  • 2.16.241.200
  • 2.16.241.211
  • 2.16.241.219
  • 2.16.241.222
  • 2.16.241.224
  • 2.16.241.218
  • 2.16.241.206
  • 2.16.241.207
  • 2.16.204.138
  • 2.16.204.151
  • 2.16.204.153
  • 2.16.204.135
  • 2.16.204.137
  • 2.16.204.148
whitelisted
login.live.com
  • 40.126.31.130
  • 40.126.31.128
  • 40.126.31.67
  • 40.126.31.3
  • 20.190.159.2
  • 40.126.31.71
  • 20.190.159.128
  • 40.126.31.1
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
google.com
  • 142.250.186.78
whitelisted
self.events.data.microsoft.com
  • 52.182.143.215
whitelisted
api.anthropic.com
  • 160.79.104.10
whitelisted
downloads.claude.ai
  • 35.190.46.17
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 184.30.131.245
whitelisted
crl.microsoft.com
  • 2.16.241.12
  • 2.16.241.19
whitelisted

Threats

PID
Process
Class
Message
5276
MoUsoCoreWorker.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
7916
firefox.exe
Attempted Information Leak
SUSPICIOUS [ANY.RUN] FingerprintJS Usage Observed in HTTP response
7916
firefox.exe
Attempted Information Leak
SUSPICIOUS [ANY.RUN] FingerprintJS Usage Observed in HTTP response
7916
firefox.exe
Attempted Information Leak
SUSPICIOUS [ANY.RUN] FingerprintJS Usage Observed in HTTP response
7916
firefox.exe
Attempted Information Leak
SUSPICIOUS [ANY.RUN] FingerprintJS Usage Observed in HTTP response
7916
firefox.exe
Attempted Information Leak
SUSPICIOUS [ANY.RUN] FingerprintJS Usage Observed in HTTP response
7916
firefox.exe
Attempted Information Leak
SUSPICIOUS [ANY.RUN] FingerprintJS Usage Observed in HTTP response
7916
firefox.exe
Attempted Information Leak
SUSPICIOUS [ANY.RUN] FingerprintJS Usage Observed in HTTP response
7916
firefox.exe
Attempted Information Leak
SUSPICIOUS [ANY.RUN] FingerprintJS Usage Observed in HTTP response
7916
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Websocket Upgrade Request
No debug info